漏洞标题
绕过由服务账户接受插件执行的可安装密钥策略
漏洞描述信息
绕过ServiceAccount接纳插件强制执行的可挂载秘密策略
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
漏洞类别
信息暴露
漏洞标题
Bypassing enforce mountable secrets policy imposed by the ServiceAccount admission plugin
漏洞描述信息
Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures pods running with a service account may only reference secrets specified in the service account’s secrets field. Kubernetes clusters are only affected if the ServiceAccount admission plugin and the `kubernetes.io/enforce-mountable-secrets` annotation are used together with ephemeral containers.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
漏洞类别
输入验证不恰当
漏洞标题
Kubernetes 安全漏洞
漏洞描述信息
Kubernetes(K8s)是云原生计算基金会(Cloud Native Computing Foundation)的一个开源系统,用于自动部署、扩展和管理容器化应用程序。 Kubernetes存在安全漏洞。攻击者利用该漏洞强制执行安装秘密策略的容器。
CVSS信息
N/A
漏洞类别
其他